{"id":"CVE-2022-29257","aliases":["GHSA-77xc-hjv8-ww97"],"url":"https://o3.security/vulnerability/CVE-2022-29257","summary":"Electron's AutoUpdater module fails to validate certain nested components of the bundle","details":"### Impact\nThis vulnerability allows attackers who have control over a given apps update server / update storage to serve maliciously crafted update packages that pass the code signing validation check but contain malicious code in some components.\n\nPlease note that this kind of attack would require **significant** privileges in your own auto updating infrastructure and the ease of that attack entirely depends on your infrastructure security.\n\n### Patches\nThis has been patched and the following Electron versions contain the fix:\n\n* `18.0.0-beta.6`\n* `17.2.0`\n* `16.2.0`\n* `15.5.0`\n\n### Workarounds\nThere are no workarounds for this issue, please update to a patched version of Electron.\n\n### For more information\nIf you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)","published":"2022-06-13T21:25:10Z","modified":"2026-08-12T03:51:35.050352095Z","cvss":{"score":6.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00869,"percentile":0.55608,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"electron","fixedVersion":"15.5.0"},{"ecosystem":"npm","name":"electron","fixedVersion":"16.2.0"},{"ecosystem":"npm","name":"electron","fixedVersion":"17.2.0"},{"ecosystem":"npm","name":"electron","fixedVersion":"18.0.0-beta.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29257.json"},{"type":"ADVISORY","url":"https://github.com/electron/electron/security/advisories/GHSA-77xc-hjv8-ww97"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29257"},{"type":"PACKAGE","url":"https://github.com/electron/electron"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.050352095Z"}}